CVE-2020-9295
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2020-9295 is a vulnerability affecting FortiOS 6.2, 6.4, and FortiClient 6.2 with AV engine versions 6.00142 and below, 6.00144 and below, and 6.00137 and below respectively. These systems may fail to detect certain malformed or non-standard RAR archives containing malicious files. FortiClient will identify malicious files upon extraction via real-time scanning. FortiGate can detect the malicious archive if Virus Outbreak Prevention is activated. This vulnerability could potentially expose systems to malware if the suspicious files are opened or extracted. Users are advised to upgrade their AV engine versions to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Fortinet FortiClient
Affected Vendors
- Fortinet